Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 334

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Tips for Parenting at a dual language school (non native)
SpaceX gives Nvidia a much-needed boost. Plus, Cramer on an 'undervalued' stock
Movie: The Egg and I
Chipmaker Broadcom is breaking out. How Tony Zhang is trading it
Manager of DRAM memory chip stock trade blockbuster ETF is back with new AI thematic bet
Google chief scientist Jeff Dean leaving in AI reshuffle after 27 years at company
Uber stock sinks 7% after weak guidance despite revenue growth
Movie: The Temptation of St. Tony
Tales from the Crypt: The Man Who Was Death
Ted Lasso: Home